GPEN Password Attacks and Formats Practice Question
What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?
⚠ Common exam trap
Many candidates think rules are used to generate completely random passwords, missing their actual purpose of modifying existing dictionary words.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To transform dictionary words into common password variations.
Rules are used to transform wordlist entries into variations. For example, a rule might take the word 'password' and generate 'Password123!' or 'P@ssw0rd'. This increases the effectiveness of dictionary attacks by covering common variations that users employ to meet complexity requirements, without needing a massive, exhaustive dictionary. This is a critical skill for testers to maximize the utility of limited wordlist sizes while increasing the likelihood of cracking complex, user-chosen passwords.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To decrypt the hash using the specified algorithm.
Why it's wrong here
Hashes are one-way functions and cannot be decrypted. The term 'decrypt' is technically incorrect in the context of password hashes. Rules are used to generate candidates for comparison against a target hash, not to perform any form of mathematical reversal on the hash value itself during the process.
- ✓
To transform dictionary words into common password variations.
Why this is correct
Rules allow for the programmatic mutation of wordlist entries. By applying rules such as appending numbers, capitalizing, or substituting characters, testers can simulate common user password patterns. This dramatically improves success rates against users who follow simple patterns to satisfy organizational password complexity policies during the cracking process.
- ✗
To automatically update the hashing algorithm to a newer standard.
Why it's wrong here
Rules do not influence the hashing algorithm itself. The algorithm is predefined by the hash type (e.g., -m 1800). Rules are strictly for manipulating the candidate plaintext input before it is passed through the hashing function for comparison against the target hash value extracted from the target system.
- ✗
To bypass account lockout mechanisms on the target system.
Why it's wrong here
Rules operate locally on the attacker's machine and have no impact on the target system's network defenses. They are purely for optimizing the search space of the dictionary attack, not for interacting with the authentication service in a way that would circumvent or bypass account lockout policies.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.